India's Budget 2025-26 cOVEAGE
Presented by:
spot_img

Indian Healthcare Faced Enormous Cyber Attacks in 2022, Till Nov: CyberPeace Foundation and Autobot Infosec Report

Date:

Trending

Cyber attacks on healthcare facilities have been rising in recent years, and the pandemic has only worsened matters. With hospitals and other healthcare facilities struggling to keep up with the demand for care, they have become an easy target for cybercriminals. While this may seem like a small amount, it can be devastating for a hospital that is already stretched thin.

- Advertisement -

Research done by CyberPeace Foundation (CPF), Autobot Infosec Private Limited, along with the academic partners under CyberPeace Center of Excellence (CCoE), has found that nearly 1.9 million attack events have been recorded in 2022 till 28th November on the Healthcare based threat intelligence sensors network simulated by the research group in India.

The study is a part of CyberPeace Foundation’s e-Kawach program to implement comprehensive public network and threat intelligence sensors across the country to capture internet traffic and analyze real-time cyberattacks that a location or an organization faces. A credible intelligence on real-time threats empowers organizations or a Country to build cybersecurity policies.

- Advertisement -

“By deploying the simulated network, we can collect data on attack patterns, the different types of attack vector for the different protocols, and the recent trends of malicious activity,” – Spokesperson, CyberPeace Foundation added.

Trends noticed by the Research

Like any other critical infrastructure worldwide, the Indian Healthcare infrastructure is also vulnerable to cyber attacks involving state & non-state actors. The Healthcare based threat intelligence sensors network deployed by the CyberPeace Foundation, Autobot Infosec Private Ltd. with the CyberPeace Center of Excellence (CCoE) partners has seen a surge in the number of cyberattacks with 1846712 hits between January 2022 to November 28th 2022 from a total number of 41181 Unique IP addresses appearing from countries like Vietnam, Pakistan, China etc.

The vulnerable internet-facing systems having Remote Desktop Protocol (RDP), vulnerable SMB and Database services enabled, and old Windows server Platforms were mostly attacked. Attackers also tried to inject malicious payloads into the network. The deployed network has captured a total of 1527 unique payloads belonging to Trojan, Ransomware, etc.

Analysis of data has drawn the attention that attackers also tried to exploit DICOM/MYSQL/MSSQL protocols to access the sensitive patients data like medical images, diagnostic databases etc. DICOM is standard protocol used in most medical and healthcare facilities for the management and transmission of medical images and related data.

Research team noticed a massive brute force, dictionary attacks were performed against the protocols FTP, MYSQL and MSSQL using some common credentials like ‘root’, ‘ftp’, ‘admin’, ‘web’, ‘web!’, ‘qwerty’, ‘password1’, ‘sql2005’, ‘passw0rd’, ‘administrator’ etc. One new trend has been noticed that attackers are nowadays using long passwords, not usually mentioned in the English dictionary, for example ‘4yqbm4,m~!@~#$%^&*(),.;’ and ‘!@#$%^&*’. Some common FTP commands were also captured – “USER”, “PASS”, “PWD”, “CWD”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “TYPE”.

In an earlier report released in August 2022, CyberPeace of Foundation also mentioned that there has been an increase in the number of phishing/social engineering attacks on Indian organizations in the Healthcare business. CPF spokesperson drew attention to WhatsApp messages masquerading as an offer from Apollo Hospital with links luring unsuspecting users with the promise of medical subsidy presents making the rounds on the app.

Recently, news has been making the rounds on the internet that All India Institute of Medical Sciences (AIIMS), Delhi faced a Cyberattack probably with the injected Ransomware on their systems.

“Cyber criminals are taking advantage of the fact that healthcare organizations are under immense strain and are more likely to pay a ransom to get their systems up and running again. Organisations should ensure their systems are secured by reducing unnecessary data, improving the patch level of software, backup and restore procedures and auditing systems to build awareness of any threats,” – Spokesperson added.

The Advisory

Do not expose critical services unnecessarily to the internet.

Network firewalls should always be patched with the latest security updates.

Isolate the critical network from the public network.

Periodically perform technical audits of Healthcare Infrastructure Devices, networks and any other end-points directly or indirectly connected to it, to identify security concerns.

Run CyberAwareness Drive by Cyber Experts at regular intervals for the team.

Develop an R&D lab to enhance CyberSecurity skills among the employees.

Maintain strong Password Policy:

Use a strong password for all devices and online accounts.

Passwords should be at least 8-13 characters long.

Passwords should contain at least one upper case (A-Z), numeric character (0-9), and a special character (!@%&….).

Where possible it is recommended to use key based authentication along with passwords.

Do not use the same password for all your online accounts. All the passwords should be different for different versions.

Try avoiding a password that consists of dictionary words.

Stay away from Phishing links: Phishing is an attempt of social engineering techniques to inject malware or obtain sensitive information such as usernames, passwords, and credit card information by spreading fake links and pretending to be acting as a trustworthy entity. Please do not click on such links before verifying the authenticity of the same.

Never share or forward fake messages containing links to any social platform without proper verification.

For more details, reach out to us at secretariat@cyberpeace.net.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

More Latest Stories

More Articles

Finbok Reviews | How Finbok A ttracts and Retains New Traders Around the Globe in 2025

In the competitive world of online trading, choosing the right platform is essential for traders at any level. With a wide range of options...

Budget 2025 Expectations: GST Overhaul Tops Budget 2025 Wishlist for Business and Global Competitiveness

As India prepares for the Union Budget 2025, business leaders are sharing their hopes for reforms aimed at fostering innovation and simplifying processes. There's a strong push for rationalizing GST rates and easing compliance, which would improve the ease of doing business. Many are...

Budget 2025 Expectations: FHRAI Expects Reforms to Boost Hospitality and Tourism Sector

The Federation of Hotel & Restaurant Associations of India (FHRAI), has outlined its expectations...

Union Budget 2025 Expectations: India Inc. Expects Tax Reforms, Startup Incentives, and Support for MSMEs

As the Union Budget 2025 approaches, Business leaders from across industries are urging Finance...

Budget 2025 Expectations: Taabi Mobility CEO Pali Tripathi says, Logistics Sector Looks for Tech and Sustainability Focus in India’s Budget 2025

With Union Budget 2025 approaching, the logistics industry highlights the need for government action...

HCLTech Partners with Carrix to Modernize Global Port Operations Using AIoT

HCLTech, a leading global technology company, today announced an agreement with Carrix, the world’s...

The Sustainable Tech That Will Simplify Life as a Homeowner

Owning a home is the ultimate dream…until it’s 7 a.m., your driveway is buried...

Powering the Future: How Digitisation is Transforming Power Transmission & Distribution

As India, the third-largest producer, and consumer of electricity worldwide with over 442 gigawatts...

Top Cybersecurity Practices for Small Businesses: Why a VPN is a Must-Have

In today's hyperconnected world, small businesses face a growing number of cybersecurity threats that can cripple operations and erode customer trust. From phishing attacks...

Equal, OneMoney Appoints Former Supreme Court Judge Justice B.N. Srikrishna as Chairman

Equal, one of India’s leading secure data sharing platforms, and its strategic investee OneMoney...

ECO Hotels & Resorts Ltd Opens 60 Room Property In Bengaluru

ECO Hotels & Resorts Limited, a stock exchange-listed mid-segment hotel chain has today said...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

Botanic Healthcare draws $30 Mn in fresh round funding

Telangana-based nutraceutical company, Botanic Healthcare today announced that it has raised ₹250 crore (approximately...

Delhi High Court Shields Upstox Trademark Rights, Targets Telegram Violators

Delhi High Court has granted an interim injunction in favor of RKSV Securities India Pvt. Ltd., also known as Upstox, restraining unknown entities from...

GPS Renewables Appoints Central Bank of India ex-MD Homai Ardeshir Daruwalla As Independent Director

GPS Renewables, an India-based biogas engineering company on Monday announced the appointment of Central Bank of India's Former Managing Director and Chairman, Homai Ardeshir Daruwalla as an Independent Director to its board. Homai Ardeshir Daruwalla currently serves as an independent director at Vizag Seaport...

Strengthening the First Line of Defense with People, Processes, and Technology

Globally and across industries, the risk landscape is growing more volatile and complex, with...

N Space Tech Launches Maiden Payload SwetchaSAT-V0 on ISRO’s POEM-4

N Space Tech, an India-based defense and aerospace startup, has successfully launched its first...

Embracing Linguistic Diversity: How Multilingual Education Supports India’s Linguistic Heritage

India is a country of rich culture, multilingualism, and heritage. It is the most...

5 Tips to Expand Your Client Base Efficiently

Growing your client base is essential for the success and sustainability of your business....

SustVest Secures $1.7 Mn in pre-Series A round

Haryana-based sustainable investment platform SustVest has raised $1.7 million in a mix of equity...

Web3 in Supply Chain: Qila’s CEO Siddharth Ugrankar On Simplifying Blockchain Adoption for Business

Speaking to TechGraph, Siddharth Ugrankar, CEO of Qila.io highlighted the potential of the company's...

Relata’s Hyper-Realism: CEO Samudragupta Talukdar On Personalized Home Buying Experiences

In an exclusive conversation with TechGraph, Samudragupta Talukdar, Founder and CEO of Relata, a...

Godrej Capital’s Gen AI Plan: CTO Jyothirlatha B on SAKSHAM AI and the Future of Financial Services

Speaking to TechGraph, Godrej Capital CTO Jyothirlatha B shared how the company is harnessing...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

Muxcap: Making Bold Moves in Innovation

Muxcap is on a mission to transform the online trading experience by combining cutting-edge...

HR Tech Impact on Employee Learning and Development

In today’s fast-paced world of work, learning and development (L&D) are no longer just...

Proxgy Snaps $3 Mn from Indian Cricketer Ajinkya Rahane and others

Proxgy, a Gurugram-based technology company specializing in virtual assistance and concierge services, has announced...

Groyyo Promotes Nitin Jain to Co-founder

B2B manufacturing technology company Groyyo has announced the promotion of its Managing Director (Exports),...

Botanic Healthcare draws $30 Mn in fresh round funding

Telangana-based nutraceutical company, Botanic Healthcare today announced that it has raised ₹250 crore (approximately...

Godrej Capital’s Gen AI Plan: CTO Jyothirlatha B on SAKSHAM AI and the Future of Financial Services

Speaking to TechGraph, Godrej Capital CTO Jyothirlatha B shared how the company is harnessing...

Preparing for a Data-Driven Future: How the GRE Assesses Academic and Analytical Readiness

As sectors such as artificial intelligence (AI) and machine learning continue to grow and...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...